Skip to content

NO-JIRA: sync with upstream 2026-09-09 - #478

Merged
openshift-ci[bot] merged 6 commits into
mainfrom
upstream-sync
Sep 14, 2026
Merged

openshift-ci[bot] merged 6 commits into
mainfrom
upstream-sync

Conversation

@openshift-ci-robot

@openshift-ci-robot openshift-ci-robot commented Sep 9, 2026 •

Copy link
Copy Markdown

🔄 Upstream Sync

Update: Mon Sep 14 08:06:03 UTC 2026

New changes detected from upstream:

lyarwood and others added 2 commits September 8, 2026 09:16
…kubevirt dependencies (containers#1411)

* ci(evals): use docker driver for kubevirt evaluation suites

When running the mcpchecker evaluation workflow on GitHub Actions
runners, build/minikube.mk defaults to using the podman driver in
rootless mode on Linux. In rootless mode, /dev/kvm is mapped to
nobody:nogroup, causing virt-handler's node-labeller init container
to fail with 'chmod: Operation not permitted' and timing out the
KubeVirt installation after 15 minutes.

Set MINIKUBE_DRIVER to docker for suites that include the kubevirt
toolset (both 'kubevirt' and 'all'). On GitHub Actions Ubuntu runners,
the Docker daemon is active and runs rootful, allowing virt-handler
to successfully initialize. Other evaluation suites continue to use
the default podman driver.

Closes: containers#1410
Signed-off-by: Lee Yarwood <lyarwood@redhat.com>

* build(kubevirt): bump KubeVirt to v1.9.0, CDI to v1.66.0, Multus to v4.3.0

Bump development dependency versions in build/kubevirt.mk:
- KubeVirt: v1.8.2 → v1.9.0
- CDI: v1.65.0 → v1.66.0
- Multus: v4.2.4 → v4.3.0

Signed-off-by: Lee Yarwood <lyarwood@redhat.com>

---------

Signed-off-by: Lee Yarwood <lyarwood@redhat.com>
Bumps the golang-x group with 4 updates: [golang.org/x/mod](https://github.com/golang/mod), [golang.org/x/oauth2](https://github.com/golang/oauth2), [golang.org/x/sync](https://github.com/golang/sync) and [golang.org/x/time](https://github.com/golang/time).


Updates `golang.org/x/mod` from 0.40.0 to 0.41.0
- [Commits](golang/mod@v0.40.0...v0.41.0)

Updates `golang.org/x/oauth2` from 0.36.0 to 0.37.0
- [Commits](golang/oauth2@v0.36.0...v0.37.0)

Updates `golang.org/x/sync` from 0.22.0 to 0.23.0
- [Commits](golang/sync@v0.22.0...v0.23.0)

Updates `golang.org/x/time` from 0.15.0 to 0.16.0
- [Commits](golang/time@v0.15.0...v0.16.0)

---
updated-dependencies:
- dependency-name: golang.org/x/mod
  dependency-version: 0.41.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
- dependency-name: golang.org/x/sync
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
- dependency-name: golang.org/x/time
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@openshift-merge-bot

Copy link
Copy Markdown

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci-robot

Copy link
Copy Markdown
Author

@openshift-ci-robot: This pull request explicitly references no jira issue.

Details

In response to this:

🔄 Upstream Sync

This PR syncs the fork with the latest upstream changes.

Changes:

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Sep 9, 2026
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (1)
  • NO-JIRA: sync with upstream

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 31a340a8-591f-46f8-ac94-931312ce84a0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested a review from bentito September 9, 2026 08:03
…ntainers#1401)

* feat(tokenexchange)!: migrate from sts_* to explicit config block

All token exchange config now is nested under a [token_exchange] block,
and the implementation is unified through the different token exchanger
implementations we have. The legacy STS exchanger is gone.

Signed-off-by: Calum Murray <cmurray@redhat.com>

* docs(tokenexchange): move from old tokenexchange format

Signed-off-by: Calum Murray <cmurray@redhat.com>

* test(e2e): verify new tokenexchange works

Signed-off-by: Calum Murray <cmurray@redhat.com>

* chore: address review comments

Signed-off-by: Calum Murray <cmurray@redhat.com>

* chore: address review comments

Signed-off-by: Calum Murray <cmurray@redhat.com>

---------

Signed-off-by: Calum Murray <cmurray@redhat.com>
@openshift-ci-robot
openshift-ci-robot force-pushed the upstream-sync branch 2 times, most recently from a76429b to d77cf89 Compare September 11, 2026 08:35
dependabot Bot and others added 3 commits September 14, 2026 07:15
)

Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.21.4 to 3.22.0.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](helm/helm@v3.21.4...v3.22.0)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@Cali0707

Copy link
Copy Markdown

/override "ci/prow/mcpchecer-eval-anthropic"

@Cali0707 Cali0707 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/approve

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Sep 14, 2026
@openshift-ci

openshift-ci Bot commented Sep 14, 2026

Copy link
Copy Markdown

@Cali0707: /override requires failed status contexts, check run or a prowjob name to operate on.
The following unknown contexts/checkruns were given:

  • ci/prow/mcpchecer-eval-anthropic

Only the following failed contexts/checkruns were expected:

  • ci/prow/e2e-aws
  • ci/prow/fips-image-scan-openshift-mcp-server
  • ci/prow/images
  • ci/prow/lint
  • ci/prow/mcpchecker-eval-anthropic
  • ci/prow/mcpchecker-eval-google
  • ci/prow/security
  • ci/prow/test
  • pull-ci-openshift-openshift-mcp-server-main-e2e-aws
  • pull-ci-openshift-openshift-mcp-server-main-fips-image-scan-openshift-mcp-server
  • pull-ci-openshift-openshift-mcp-server-main-images
  • pull-ci-openshift-openshift-mcp-server-main-lint
  • pull-ci-openshift-openshift-mcp-server-main-mcpchecker-eval-anthropic
  • pull-ci-openshift-openshift-mcp-server-main-mcpchecker-eval-google
  • pull-ci-openshift-openshift-mcp-server-main-security
  • pull-ci-openshift-openshift-mcp-server-main-test
  • tide

If you are trying to override a checkrun that has a space in it, you must put a double quote on the context.

Details

In response to this:

/override "ci/prow/mcpchecer-eval-anthropic"

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Sep 14, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Cali0707, openshift-ci-robot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 14, 2026
@Cali0707

Copy link
Copy Markdown

/override "ci/prow/mcpchecker-eval-anthropic"

@openshift-ci

openshift-ci Bot commented Sep 14, 2026

Copy link
Copy Markdown

@Cali0707: Overrode contexts on behalf of Cali0707: ci/prow/mcpchecker-eval-anthropic

Details

In response to this:

/override "ci/prow/mcpchecker-eval-anthropic"

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci

openshift-ci Bot commented Sep 14, 2026

Copy link
Copy Markdown

@openshift-ci-robot: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-ci
openshift-ci Bot merged commit b1b2a96 into main Sep 14, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants